Dark River
2023-09-27 • Ptsecurity • Dark River. You can't see them, but they're there
Positive Technologies identified this activity in October 2022 after investigating an intrusion at a Russian industrial enterprise, where it found a previously unseen modular backdoor it named MataDoor, and named the operator Dark River after the word River found in phishing-document author metadata. The likely initial vector was a phishing email with a DOCX attachment exploiting a Microsoft MSHTML vulnerability, sent to Russian defense-industry organizations in August and September 2022; researchers linked this wave to a similar September 2021 campaign using the same vulnerability and identical URL-encoding technique against Russian defense and government targets, indicating the actor has operated since at least 2021. Payloads and later backdoor samples were signed with Sectigo certificates and used Namecheap-registered command-and-control domains that did not overlap between victims. MataDoor is built around a kernel and functional and network plugins, uses AES-encrypted configuration data, and disguises its files as legitimate software already present on infected hosts. Kaspersky separately linked a related backdoor variant to Lazarus group activity, though Positive Technologies could not independently confirm the operator's identity.
-
34
Related Actors
-
232
Related Reports